BMW 2026+ Sec4Diag Coding: Software Updates and New Module Coding

A technically careful guide to BMW NA5, SP25 and Sec4Diag: which 2026+ vehicles are affected, how authenticated diagnostics differ from coding, and what remote software and new-module work requires.

TempaDrive

BMW Remote Coding Specialists

Technical Insights
August 21, 2026
23 min read
0 views
BMW 2026+ Sec4Diag Coding: Software Updates and New Module Coding

BMW 2026+ Sec4Diag Coding: Software Updates and New Module Coding

The newest BMW generation is creating a familiar problem with unfamiliar names. Workshops see NA5, SP25, Sec4Diag, NCD 3.0 and reports of a ZDF firewall, then hear that the cars are completely locked. Some of that reflects real security changes. Some of it mixes a vehicle code, a software architecture, a diagnostic service and several independent authorization systems into one story.

This guide separates those layers, explains which BMWs “2026+” refers to and describes the three Tempadrive services currently considered for compatible new-generation cars: coding, software updates and coding a supported new module after replacement. If you already know the required operation, request a VIN check through our BMW 2026+ Remote Coding & Software Updates service.

Last technical review: 21 August 2026. Vehicle and backend support can change with BMW software, certificate and tool releases. Compatibility is confirmed again before every session.

The short answer

  • NA5/NA05 is the vehicle-series designation used for the Neue Klasse BMW iX3.
  • SP25 is used for a vehicle software-architecture or service-pack family. It is not a chassis code and not the diagnostic protocol.
  • Sec4Diag refers to secure diagnostic access in the BMW tool ecosystem. Public standards and implementation evidence point to protected DoIP communication plus authenticated UDS access, including Service 0x29.
  • Diagnostic authentication, secure coding data, feature entitlement and ECU validation are different gates. Passing one does not automatically grant the others.
  • BMW officially documents remote diagnosis through Connected RMI for eligible vehicles, but its public API does not list arbitrary variant coding, complete ECU flashing or replacement-module binding.
  • Tempadrive's confirmed commercial scope is coding, software updates and coding supported new replacement modules. Region changes are not currently supported for this generation.

What the Tempadrive service includes

This is a Remote Services product, not an FSC-code product. An FSC delivery and a secure remote vehicle-programming session solve different problems and should not share a category or checkout route.

OperationPurposeWhat must be checked first
Remote codingCode an existing supported ECU or apply the correct vehicle configuration after legitimate repair or retrofit workVIN, production date, I-level, exact ECU and requested change
Software updateUpdate a supported vehicle or control unit through the secure programming workflowCurrent I-level, target path, interface, stable network and regulated battery support
New-module codingCode a supported new replacement control unit to the vehicle configurationVIN, complete part number, new-part status, coding route and any additional validation requirement

Used modules are not included automatically. Depending on the ECU and workflow, a used unit can face component-protection, validation, entitlement or donor-state restrictions. Region conversion is also excluded from the advertised new-generation scope.

Equipment required for a remote session

  • BMW-compatible ENET cable (OBD to Ethernet);
  • Windows 10/11 64-bit laptop;
  • Ethernet port or compatible USB-to-Ethernet adapter;
  • stable internet, normally through Wi-Fi or a second network adapter while ENET is connected;
  • regulated automotive power supply for software updates and new-module work;
  • an attendant at the vehicle throughout the session.

An ordinary Bluetooth OBD adapter is not a substitute for ENET. The cable supplies the local IP connection to the car; it does not supply a Sec4Diag identity, authenticated role, signed coding data or programming logic. Those belong to the secure tool and service workflow.

Does “BMW 2026+” mean every model-year 2026 car?

No. BMW sold a mixture of architectures during 2026. Some vehicles introduced Neue Klasse or related next-generation electronics, while other 2026 registrations and model-year cars remained on earlier platforms. Marketing only from the registration year would therefore be inaccurate.

The precise wording is “supported new-generation BMW vehicles from 2026 onward.” “BMW 2026+ remote coding” remains useful as a short search phrase, but VIN, production date, I-level, service-pack value where available, ECU and requested operation must decide the actual service route.

Correcting the BMW model codes

The new BMW iX3 is NA5, not G45

BMW describes the new iX3 as its first series-production Neue Klasse vehicle. The vehicle is widely identified by the technical series NA5 or zero-padded NA05. BMW's launch material confirms a newly developed electronics and software architecture, four high-performance “superbrain” computers and European market launch in spring 2026.

G45 is a different car: the combustion/PHEV fourth-generation BMW X3 introduced in 2024. It is not the Neue Klasse iX3. A successful G45 coding session is therefore not proof that an NA5 write operation uses the same permissions.

Official sources: BMW iX3 / Neue Klasse launch material and BMW G45 X3 launch information.

The updated G70 is model year 2027 in the US

BMW unveiled the updated 7 Series in April 2026. BMW USA identifies it as the 2027 BMW 7 Series and states that global production and worldwide market launch begin in July 2026. The update brings BMW Panoramic iDrive, BMW Operating System X and technologies derived from Neue Klasse.

That makes the G70 LCI relevant to the secure-service transition, but marketing descriptions do not prove its exact servicePack value or permission set. Those values must come from a real VIN and vehicle session.

Official source: BMW USA — The New BMW 7 Series.

The new BMW i3 is the second Neue Klasse model

BMW's public material calls the new i3 the second Neue Klasse model. Pre-series vehicles were built in Munich in February 2026, and BMW announced series production from August 2026. The internal designation NA0/NA00 is commonly reported, but it should be presented as a reported code until BMW uses it clearly in customer-facing technical material.

Official sources: first pre-series BMW i3 vehicles and BMW i3 series-production start.

G65 officially exists

BMW officially uses G65 for the fifth-generation X5. Series production begins in August 2026, the first market variants follow in late November, and the all-electric iX5 is scheduled for early 2027.

Official source: The new BMW X5.

BMW confirms a fully electric M, but not every rumoured name

BMW M has confirmed fully electric production from 2027 and describes an architecture with four electric motors, one per wheel. Reports commonly call the future production vehicle an electric M3 and use the code ZA0, but those exact retail and series names were not confirmed in the official BMW sources reviewed for this article. The defensible wording is “the first fully electric BMW M” until BMW confirms the production identity.

Official source: BMW's fully electric M announcement.

What SP25 means

SP25 should not be treated as a vehicle code or a replacement name for DoIP. BMW's Connected RMI API exposes a servicePack value and describes it as the version of the vehicle software architecture. That is the clearest public explanation of the category.

LayerExampleWhat it tells you
Vehicle seriesNA05Which technical vehicle family is connected
Software architecture / service packSP25, if the vehicle reports itThe software-architecture generation
Integration levelA dated I-level such as NA05-26-07-xxxThe installed software shipment
Operating system / user interfaceBMW Operating System XThe customer-facing display and app environment
Diagnostic path and securityDoIP, TLS, UDS authentication and BMW permissionsHow the tester connects and what it may request

Never approve a job from “2027 BMW” or “SP25” alone. Two cars can share a registration year yet expose different software architectures, ECUs and authorized operations.

Official source: BMW Connected RMI API documentation.

What Sec4Diag means technically

No public BMW document found for this review defines Sec4Diag as one standalone “new protocol.” The available evidence fits a layered secure diagnostic environment.

DoIP provides the IP diagnostic path

Diagnostics over Internet Protocol carries diagnostic traffic over an IP network. The current ISO 13400-2 specification includes TLS-related provisions. A protected channel can authenticate endpoints and prevent an old unprotected client from behaving as though physical OBD access alone were sufficient.

Standards source: ISO 13400-2:2025.

UDS Service 0x29 authenticates the diagnostic client

Unified Diagnostic Services includes Service 0x29, Authentication. Instead of relying only on a traditional seed/key step, a vehicle can identify a diagnostic client with certificates and grant a role-specific set of permissions. Authorization can be limited to a vehicle, ECU, function, technician role, operation or time window.

AUTOSAR diagnostic specifications describe the authentication service and related security requirements. These standards explain the building blocks; they do not disclose BMW's complete proprietary permission policy.

Standards sources: AUTOSAR Adaptive Platform Diagnostics and AUTOSAR diagnostic security requirements.

The reported ZDF firewall is another layer

BMW technical communities use ZDF for a reported central diagnostic firewall that blocks unauthenticated offline tool traffic on newer vehicles. The behaviour is plausible because an encrypted connection and authenticated tester still need a policy decision about which service may reach which ECU. However, the exact name and complete permission model were not found in public BMW documentation, so ZDF must remain clearly labelled as community-reported rather than an official specification.

Why diagnostics, coding and module binding must be separated

“Diagnostics and coding” is too broad for a secure architecture. At least six independent gates can affect the result:

  1. Transport security: can the tester establish the required protected DoIP connection?
  2. Tester authentication: can it complete Service 0x29, and which role does that identity receive?
  3. Gateway policy: may that role send the requested diagnostic service to the target ECU?
  4. Secure coding data: does the workflow have valid signed coding data? Community labels such as NCD 2.0 or NCD 3.0 concern coding-data security and are not synonyms for Sec4Diag.
  5. Feature entitlement: does the vehicle have the required SFA/SWT authorization or legitimate activation token?
  6. ECU validation / component protection: can a replacement unit be validated and associated with the vehicle, and is it new or used?

This explains a common outcome: a tool can identify a vehicle and read DTCs but cannot write coding data. Another route may code an existing ECU but cannot validate a replacement module. Neither result proves that the vehicle is fully unlocked.

BMW's workshop information describes ECU Validation as part of replacement-control-unit work and warns that the official workflow does not provide used-part installation codes. See the BMW AOS site-information guide.

Is remote diagnosis possible without Radmin?

Yes. BMW Connected RMI is the clearest official example. On supported vehicles, an independent operator can create an authorized remote session with customer agreement. Depending on the vehicle and session type, the published interface can expose vehicle data, ECU lists, DTCs, snapshots, Check Control Messages, supported DTC clearing, ECU resets and selected ECU jobs.

That is a telematics-based diagnostic route through BMW's backend. It is different from taking control of a Windows laptop through Radmin, TeamViewer or AnyDesk. The public Connected RMI functions reviewed here do not list arbitrary variant coding, complete ECU programming or replacement-module validation.

Official sources: BMW Connected RMI overview, integration documentation and pricing.

The official AOS / ISTA route

BMW AOS provides independent professional operators with diagnosis, test plans and ISTA programming. BMW recommends an appropriate professional interface and workshop-grade preparation. Programming makes power loss and network interruption the two immediate operational risks, so regulated battery support, wired vehicle communication and a defined recovery procedure matter more than the brand of remote-desktop application.

AOS access is governed by professional-use conditions. A provider should not base a commercial workflow on casual credential sharing or describe restricted backend access as a permanent vehicle bypass.

Official sources: BMW AOS technical requirements, AOS price list and AOS conditions of use.

What a serious SP25 service should verify

A compatibility record should document the exact operation, not place one universal green tick next to a model name. A responsible session record includes:

  • masked VIN, market and production date;
  • vehicle series and current I-level;
  • service-pack information where available;
  • tool and interface versions;
  • authentication outcome and exposed role/expiry information;
  • successful ECU communication and relevant diagnostic result;
  • the exact coding, programming or validation operation;
  • new or used status of a replacement ECU;
  • after-check and recovery evidence.

Useful status labels are Listed (the vehicle belongs to the generation), Diagnostic tested (a logged read/clear or supported job exists) and Write tested (that exact coding, programming or validation operation has a verified successful result). Tempadrive does not publish a production model as fully supported until the relevant operation has been tested.

Current model-year outlook

VehicleCareful wordingRelevant timing
BMW iX3NA5/NA05, first Neue Klasse model2026 market generation
BMW X3G45, not the iX3From late 2024
BMW 7 Series updateG70 LCIJuly 2026 / model year 2027 US
BMW i3Second Neue Klasse model; NA0 commonly reportedSeries production August 2026
BMW X5G65Production August 2026; market late November
BMW iX5First fully electric X5Early 2027
Fully electric BMW MBMW M Concept Neue Klasse previews the technologyProduction announced from 2027

BMW says Neue Klasse technologies will spread to more than 40 new or updated models by the end of 2027. That does not mean every one of those cars has an identical SP25 diagnostic or coding implementation.

Common questions

Does a Sec4Diag error prove the car uses SP25 security?

No. A Sec4Diag-labelled exception can also be a generic tool, certificate, interface or software-version error. Diagnose the connection and vehicle data before concluding that the new architecture blocked the session.

Is NCD 3.0 the same as Sec4Diag?

No. NCD terminology concerns coding data and signatures. Sec4Diag concerns secure diagnostic access. One layer can succeed while another still blocks the requested write operation.

Is every 2026 or 2027 BMW secured in exactly the same way?

No. Production date, electrical architecture, service pack, I-level, ECU and requested operation all matter. G45, NA5, G70 LCI and G65 should not be treated as one identical platform.

Can an ENET cable handle the job?

ENET provides the local vehicle connection and is required for the Tempadrive workflow. The cable alone does not supply a Sec4Diag certificate, authenticated role, signed coding data or programming logic.

Can a used module be remotely bound?

Used-module support depends on the exact ECU and workflow, and official validation can restrict donor units. Verify the VIN, part number, donor state and authorization route before buying or installing the module.

Are region changes supported on these new-generation cars?

No. Region changes are not currently included in the advertised BMW 2026+ service. Older compatible BMW architectures remain available through the normal Remote Services catalogue.

Legal remote access is becoming more explicit in the EU

EU vehicle-repair legislation protects independent-operator access to repair and maintenance information. Regulation (EU) 2018/858 covers non-discriminatory access and remote diagnostics. Delegated Regulation (EU) 2026/699 also defines a Remote Service Supplier and develops identity, authorization and logging requirements.

That is not permission to bypass vehicle security. A commercial provider still needs customer authorization, legitimate credentials, privacy controls, logs and compliance with the relevant tool and manufacturer terms. Security-related repair information remains subject to the EU SERMI framework.

Final conclusion

Neue Klasse-era BMWs are not simply impossible to diagnose or code. The real change is that physical OBD access and an old offline tool no longer imply broad authority. A series code such as NA05 identifies the vehicle, the service-pack value identifies a software-architecture generation, protected DoIP carries diagnostic traffic, UDS Service 0x29 authenticates a tester, gateway policy controls allowed services, and coding, activation and ECU validation add separate permissions.

For supported new-generation BMW vehicles from 2026 onward, Tempadrive offers three carefully defined Remote Services: coding, software updates and coding a supported new module after replacement. VIN, production date, software level, ECU and operation are checked before booking. Region changes are not currently supported.

Need a compatibility check? Open the BMW 2026+ Remote Coding & Software Updates service and send the VIN privately, country, required operation, ECU part number if applicable, and confirmation that an ENET cable, Windows laptop and suitable power supply are available.

BMW 2026+ Sec4Diag Coding & Updates Explained | TempaDrive